Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
466 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.43% | — | Tensoropera FedmlAI | 14/9/2026 | 14/9/2026 | A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote… | |
| Pendiente de análisis | Alta (7.7) | 0.40% | — | Tensorzero GatewayAI | 21/8/2026 | 11/9/2026 | TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage]… | |
| En análisis | Media (5.4) | 0.16% | — | Intel Extension FOR TensorflowAI | 11/8/2026 | 12/8/2026 | Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Media (6.2) | 0.16% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.4) | 0.16% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Aplazada | Alta (7.8) | 0.35% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service. | |
| Aplazada | Alta (7.5) | 0.31% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service. | |
| Aplazada | Media (6.2) | 0.16% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.8) | 0.21% | — | Nvidia Tensorrt | 14/7/2026 | 17/7/2026 | NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution. | |
| Aplazada | Media (6.2) | 0.16% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.8) | 0.22% | — | Nvidia Tensorrt | 14/7/2026 | 17/7/2026 | NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution. | |
| Aplazada | Media (6.4) | 0.18% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.21% | — | Nvidia Tensorrt | 14/7/2026 | 17/7/2026 | NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution. | |
| Aplazada | Media (6.8) | 0.15% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure. | |
| Aplazada | Alta (8.4) | 0.39% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data… | |
| Aplazada | Alta (7.3) | 0.16% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and… | |
| Analizada | Crítica (9.8) | 1.0% | — | Nvidia Tensorrt | 14/7/2026 | 17/7/2026 | NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution. | |
| Aplazada | Media (6.3) | 0.16% | — | Nvidia Tensorrt-llmAI | 14/7/2026 | 15/7/2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Media (6.4) | 0.33% | — | Nvidia Tensorrt-llm | 14/7/2026 | 22/9/2026 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution. | |
| Analizada | Alta (7.5) | 0.39% | — | Nvidia Tensorrt | 20/5/2026 | 23/7/2026 | NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering. | |
| Analizada | Crítica (9.8) | 0.59% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure. | |
| Analizada | Alta (7.5) | 0.47% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Crítica (9.8) | 0.38% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Crítica (9.8) | 0.57% | — | Nvidia Tensorrt LLM | 20/5/2026 | 24/7/2026 | NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure. | |
| Analizada | Media (6.9) | 0.62% | — | Tensoropera Fedml | 5/4/2026 | 24/7/2026 | A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not… |